Description
When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-38198 | When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request |
References
History
No history.
Status: PUBLISHED
Assigner: Ping Identity
Published:
Updated: 2024-09-10T15:05:08.099Z
Reserved: 2023-07-25T20:13:14.876Z
Link: CVE-2023-34085
Updated: 2024-08-02T16:01:53.879Z
Status : Modified
Published: 2023-10-25T18:17:28.010
Modified: 2024-11-21T08:06:30.577
Link: CVE-2023-34085
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD